Security advisory: Authenticat... Note

Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)

Posted by disclosure via Fulldisclosure on Aug 170day Rubbish Research Team is publicly disclosing a vulnerability in Scrutinizer 19.7.0 (Plixer). The research is published and a proof-of-concept is available. Authenticated RCE (SQL injection) (CVSS 8.8, authenticated) Plixer Scrutinizer 19.7.0 concatenates the HTTP orderBy parameter directly into a SQL ORDER BY clause with no escaping in the adminEditLang handler. The default configuration includes the pg_cron extension and a PostgreSQL...